
GDPR for Small Charities: What You're Legally Required to Have Online
05/05/26, 09:00
GDPR applies to every UK charity with a website — regardless of size. Here is what you are legally required to have in place online, and what the most common gaps look like.
Most small charity trustees have heard of GDPR. Far fewer are confident they actually understand what it requires of their organisation — particularly online. And fewer still have taken the time to audit their website and digital systems against the legal standard they are supposed to meet.
This is not a criticism. Running a small charity is demanding, compliance expertise is expensive, and the guidance available online ranges from genuinely helpful to thoroughly confusing. But GDPR is not optional, and the consequences of getting it wrong — however unintentionally — can be serious enough to warrant taking it seriously now rather than waiting until a problem forces the issue.
This article covers what UK charities are legally required to have in place online, what the most common gaps look like, and what to do if you are not sure where your organisation currently stands.
A quick note on the legal framework
The UK General Data Protection Regulation — UK GDPR — came into effect when the UK left the European Union and is now the primary data protection law governing how organisations handle personal information in the United Kingdom. It sits alongside the Data Protection Act 2018 and is enforced by the Information Commissioner's Office, known as the ICO.
UK GDPR applies to any organisation that collects, stores, or processes personal data — which includes names, email addresses, phone numbers, IP addresses, and any other information that can identify a living individual. If your charity has a website with a contact form, a donation page, a newsletter sign-up, or any kind of user account system, you are collecting personal data and UK GDPR applies to you.
There are no exemptions for small charities. The law applies regardless of your organisation's size or turnover.
What your website must have
Your privacy policy
Every charity website that collects any form of personal data must have a privacy policy. This is a legal requirement, not a recommendation.
Your privacy policy must be written in plain English that a member of the public can understand. It must explain what personal data you collect, why you collect it, what legal basis you rely on for processing it, how long you keep it, whether you share it with any third parties, and how individuals can exercise their rights under UK GDPR — including their right to access, correct, or request deletion of their data.
A privacy policy buried in the footer that was copied from a template and never reviewed is better than nothing — but only just. If your policy describes data practices that do not reflect what your organisation actually does, it is not compliant and could create more problems than it solves.
A cookie consent mechanism
If your website uses cookies — and almost every website does — you are legally required to obtain informed consent from visitors before placing non-essential cookies on their devices. This means a cookie banner or consent tool that clearly explains what cookies you use, gives visitors a genuine choice to accept or decline them, and records their preference.
Cookies used for analytics, advertising, or tracking visitor behaviour are non-essential and require consent. Cookies that are strictly necessary for the website to function — such as those that keep a user logged in — do not require consent but must still be disclosed.
A cookie banner that says "We use cookies. By using this site you agree to our cookie policy" and provides no opt-out does not meet the legal standard. The ICO has been clear on this point, and enforcement action for non-compliant cookie practices has increased in recent years.
A secure connection
Your website must be served over HTTPS — the padlock icon in the browser address bar. This encrypts data transmitted between your visitors' devices and your website, protecting information entered into contact forms, donation pages, and any other input fields.
A website without HTTPS is not only a legal risk — it is also flagged by most modern browsers as "Not Secure," which will deter visitors and undermine donor confidence before they have read a single word of your content.
Contact and donation forms
Every form on your website that collects personal information must be accompanied by a clear statement explaining how that information will be used, a link to your privacy policy, and — where relevant — an explicit opt-in for any marketing communications. Pre-ticked boxes are not permitted under UK GDPR. Consent must be freely given, specific, informed, and unambiguous.
If your charity uses a third-party donation platform, you need to be clear with donors about which organisation is handling their data and under what terms. Pointing donors to a payment processor without any explanation of the data relationship is a gap that the ICO would take a dim view of.
What else your organisation needs
Beyond the website itself, UK GDPR requires your charity to maintain a Record of Processing Activities — a document that maps out what personal data you hold, where it came from, why you hold it, who has access to it, and how long you keep it. This does not need to be published publicly, but it must exist and be kept up to date.
You must also have a process for responding to Subject Access Requests — when an individual asks to see the personal data you hold about them. You have one calendar month to respond.
And if your charity suffers a data breach — whether that is a staff laptop being lost, an email sent to the wrong person, or an unauthorised access to your systems — you may be required to report it to the ICO within 72 hours. Knowing what constitutes a reportable breach, and having a process in place to respond quickly, is a basic requirement that many small charities have never thought through.
The most common gaps
In practice, the most common compliance gaps for small charities are:
A privacy policy that has never been reviewed or updated since it was first written.
A cookie banner that does not provide a genuine opt-out.
Contact forms with no privacy notice attached.
No formal process for handling Subject Access Requests.
None of these are difficult to fix. But they do require someone to actually do the work — to review the current position, identify the gaps, and put the right language and processes in place.
Where to start
The ICO provides free guidance specifically for charities and small organisations at ico.org.uk. Their Small Business and Charity hub is genuinely practical and worth reading before you spend money on external advice.
Start with your privacy policy — read it as if you were a first-time visitor to your site and ask honestly whether it reflects what your organisation actually does with people's data. Then check your cookie consent mechanism, review your contact forms, and make sure your HTTPS certificate is active and current.
If your website was built by a third party and you are not sure what data it collects or how it is configured, that conversation needs to happen sooner rather than later. Data protection responsibility sits with your charity as the data controller — not with your website developer.
For registered UK charities working with Linkbit, GDPR compliance is built into every website we deliver as standard. If you are not sure where your current setup stands, start with a conversation.
Ready to make sure your charity's digital presence is compliant and properly managed? Start your Discovery Session
.jpg)
.jpg)
